ConcurDB: Concurrent Query Authentication for Outsourced Databases

ConcurDB: Concurrent Query Authentication for Outsourced Databases
复制标题

ConcurDB:外包数据库的并发查询身份验证

DOI:
--
复制
发表时间:
2019
影响因子:
8.9
通讯作者:
R. Sion
R. Sion
中科院分区:
计算机科学2区
文献类型:
--
作者:
Sumeet Bajaj;Anrin Chakraborti;R. Sion

文献摘要

被引文献

相似文献

外包数据库的客户需要查询身份验证(Query Authentication, QA)来保证可能受到损害的提供者返回的查询结果的完整性和真实性。先前的工作通过部署几个基于软件的加密构造为有限的查询类提供QA保证。这些结构通常被设计为只读或不经常更新的数据库。对于动态数据集,数据所有者需要代表客户端执行所有更新。因此,对于多个客户机的并发更新,例如OLTP工作负载,现有的QA解决方案是低效的。我们提出了ConcurDB,一个允许多个客户端同时更新的并发QA方案。为了实现并发QA,我们设计了几个新的机制。首先,我们确定并使用QA和内存检查之间的重要关系来解耦查询执行和验证。我们允许客户端并发地执行事务,并使用基于离线内存检查的协议并行地执行验证。然后,为了将QA扩展到多客户端场景,我们设计了新的协议,使客户端即使在使用不受信任的提供者作为通信中心时也能安全地交换一小组身份验证数据。最后,我们克服了提供者端的重放攻击。使用ConcurDB,我们为完整的TPC-C基准测试提供并评估并发QA。对于更新,ConcurDB的性能比现有解决方案提高了4倍。
Clients of outsourced databases need Query Authentication (QA) guaranteeing the integrity and authenticity of query results returned by potentially compromised providers. Prior work provides QA assurances for a limited class of queries by deploying several software-based cryptographic constructs. The constructs are often designed assuming read-only or infrequently updated databases. For dynamic datasets, the data owner is required to perform all updates on behalf of clients. Hence, for concurrent updates by multiple clients, such as for OLTP workloads, existing QA solutions are inefficient. We present ConcurDB, a concurrent QA scheme that enables simultaneous updates by multiple clients. To realize concurrent QA, we have designed several new mechanisms. First, we identify and use an important relationship between QA and memory checking to decouple query execution and verification. We allow clients to execute transactions concurrently and perform verifications in parallel using an offline memory checking based protocol. Then, to extend QA to a multi-client scenario, we design new protocols that enable clients to securely exchange a small set of authentication data even when using the untrusted provider as a communication hub. Finally, we overcome provider-side replay attacks. Using ConcurDB, we provide and evaluate concurrent QA for the full TPC-C benchmark. For updates, ConcurDB shows a 4x performance increase over existing solutions.